First published: Thu Oct 02 2014(Updated: )
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen XAPI | <=4.4.0 | |
Xen XAPI | =3.0.2 | |
Xen XAPI | =3.0.3 | |
Xen XAPI | =3.0.4 | |
Xen XAPI | =3.1.3 | |
Xen XAPI | =3.1.4 | |
Xen XAPI | =3.2.0 | |
Xen XAPI | =3.2.1 | |
Xen XAPI | =3.2.2 | |
Xen XAPI | =3.2.3 | |
Xen XAPI | =3.3.0 | |
Xen XAPI | =3.3.1 | |
Xen XAPI | =3.3.2 | |
Xen XAPI | =3.4.0 | |
Xen XAPI | =3.4.1 | |
Xen XAPI | =3.4.2 | |
Xen XAPI | =3.4.3 | |
Xen XAPI | =3.4.4 | |
Xen XAPI | =4.0.0 | |
Xen XAPI | =4.0.1 | |
Xen XAPI | =4.0.2 | |
Xen XAPI | =4.0.3 | |
Xen XAPI | =4.0.4 | |
Xen XAPI | =4.1.0 | |
Xen XAPI | =4.1.1 | |
Xen XAPI | =4.1.2 | |
Xen XAPI | =4.1.3 | |
Xen XAPI | =4.1.4 | |
Xen XAPI | =4.1.5 | |
Xen XAPI | =4.1.6.1 | |
Xen XAPI | =4.2.0 | |
Xen XAPI | =4.2.1 | |
Xen XAPI | =4.2.2 | |
Xen XAPI | =4.2.3 | |
Xen XAPI | =4.3.0 | |
Xen XAPI | =4.3.1 | |
Xen XAPI | =4.4.0 | |
Xen XAPI | =4.4.0-rc1 | |
Debian | =7.0 | |
Fedora | =19 | |
Fedora | =20 | |
SUSE Linux | =12.3 | |
SUSE Linux | =13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7155 has a medium severity rating due to its potential to allow local users to crash the guest system or escalate privileges.
To fix CVE-2014-7155, upgrade to the latest Xen version that incorporates the necessary patches.
CVE-2014-7155 affects Xen versions 4.4.x and earlier, along with multiple specific earlier versions.
Yes, CVE-2014-7155 can potentially lead to security breaches by allowing local users to gain kernel mode privileges.
Local users of HVM guests running vulnerable versions of Xen are impacted by CVE-2014-7155.